How to implement ISO 38505: Step-by-step guide
Data now influences almost every important business decision. Organizations use it to understand customers, manage financial performance, operate critical systems, train AI models, measure risk, automate processes, and make strategic decisions.
As the importance of data increases, organizations need more than technical data management. They need clear accountability for how data is collected, used, protected, shared, retained, and ultimately disposed of.
ISO/IEC 38505-1:2026 applies the governance principles and model of ISO/IEC 38500 specifically to data. It provides guidance to governing bodies on the effective, efficient, and acceptable use of data and applies to data created, collected, stored, secured, protected, or controlled through IT systems.
However, organizations looking to implement ISO 38505 should understand an important point from the beginning: this is a principles-based governance standard. Implementation should therefore focus on building effective governance arrangements around data rather than treating the standard as a simple checklist.
This step-by-step guide explains how organizations can translate ISO 38505 into a practical data governance programme.
- What does it mean to implement ISO 38505?
- Before you implement ISO 38505: Understand the current standard
- Step 1: Establish executive sponsorship and governance accountability
- Step 2: Identify stakeholders and understand their expectations
- Step 3: Understand your current data environment
- Step 4: Assess the current state of data governance
- Step 5: Define the desired data governance outcomes
- Step 6: Establish a data governance policy
- Step 7: Establish data accountability across the lifecycle
- Step 8: Develop a risk-based data classification model
- Step 9: Identify and assess data-related risks
- Step 10: Map legal, regulatory, contractual, and policy constraints
- Step 11: Design and implement appropriate controls
- Step 12: Apply the Evaluate, Direct and Monitor governance cycle
- Step 13: Establish meaningful data governance metrics
- Step 14: Integrate data governance with cyber security, privacy, AI, and GRC
- Step 15: Maintain evidence and governance records
- Step 16: Monitor controls and identify governance gaps
- Step 17: Review and continually improve your ISO 38505 implementation
- Common mistakes when implementing ISO 38505
- How long does it take to implement ISO 38505?
- Is ISO 38505 certification required?
- ISO 38505 implementation checklist
- Conclusion: Implement ISO 38505 with a connected GRC approach
- Frequently asked questions about implementing ISO 38505
What does it mean to implement ISO 38505?
To implement ISO 38505 means establishing governance structures that enable the organization to make accountable, informed, and responsible decisions about data.
The standard distinguishes governance from operational data management. Governance is concerned with how the governing body evaluates the organization’s use of data, establishes direction, and monitors whether expectations are being met. Operational teams then manage data within that governance environment.
This distinction matters because many organizations already have data management processes but still lack effective data governance.
For example, an IT team may know where customer data is stored and how it is backed up. A security team may know which technical controls protect it. A privacy team may understand applicable regulatory obligations. Yet senior leadership may still lack a clear answer to questions such as who is accountable for the data, whether its use supports business objectives, whether its risks are acceptable, and whether governance expectations are being followed.
Implementing ISO 38505 helps close this gap.
Before you implement ISO 38505: Understand the current standard
Organizations beginning an ISO 38505 project should work from the correct edition.
ISO/IEC 38505-1:2026 is the current edition and replaced ISO/IEC 38505-1:2017. It was published in August 2026 and applies the principles and governance model of ISO/IEC 38500 to the governance of data.
The standard applies to organizations of all sizes, including private businesses, public companies, government entities, and not-for-profit organizations. Its relevance is also not determined by how heavily an organization depends on data.
Implementation should therefore be proportionate to the organization’s size, business model, regulatory exposure, data environment, risk profile, and governance maturity.
Step 1: Establish executive sponsorship and governance accountability
The first step to implement ISO 38505 is to establish clear ownership at the governance level.
Data governance cannot operate effectively when responsibility is delegated entirely to IT, cyber security, privacy, or compliance teams. These functions have important operational and advisory roles, but ISO 38505 addresses governance at a higher organizational level.
The governing body should understand why data matters to the organization, which major risks and opportunities are associated with its use, and how accountability for data-related decisions will be established.
Depending on the organization’s structure, this may involve the board, executive management, a data governance committee, a risk committee, or another formal governance structure.
Define responsibilities clearly
Organizations should document responsibilities for important data governance activities.
This includes identifying who owns important datasets, who manages them operationally, who defines policies, who evaluates risk, who approves significant uses of data, who monitors controls, and who receives escalation when governance expectations are not met.
Responsibility should extend beyond technical custody.
For example, the team operating a database may be responsible for its availability and technical security, but a business data owner may need to remain accountable for how the information is used, its quality, its classification, and whether access remains appropriate.
The objective is to ensure that important data does not exist without meaningful accountability.
Step 2: Identify stakeholders and understand their expectations
Data governance affects a wide range of stakeholders.
Internally, stakeholders can include the governing body, executive leadership, business units, IT, cyber security, legal, privacy, risk, compliance, internal audit, data teams, and employees.
External stakeholders may include customers, regulators, suppliers, business partners, shareholders, auditors, and service providers.
An effective ISO 38505 implementation should consider how decisions involving data affect these different groups.
For example, a new analytics programme may provide significant commercial value, but the organization also needs to consider privacy expectations, security requirements, contractual restrictions, data quality, regulatory obligations, and potential consequences for customers.
Stakeholder engagement helps governing bodies understand these different perspectives before setting direction.
Step 3: Understand your current data environment
Organizations cannot govern data effectively if they have limited visibility into what data exists.
A practical implementation should therefore establish an adequate understanding of the organization’s data landscape.
This does not necessarily mean documenting every individual record. The objective is to identify important categories of data and understand how they move through the organization.
Teams should examine data created internally, information collected from customers and employees, third-party datasets, cloud-hosted information, machine-generated data, analytics datasets, information used by AI systems, and other strategically or operationally important data.
Map the data lifecycle
ISO 38505 places significant emphasis on data accountability across the way data is handled.
Organizations should consider accountability across activities including:
- Collecting data.
- Storing data.
- Reporting information.
- Using data to make decisions.
- Distributing or sharing data.
- Disposing of data.
Mapping these activities helps reveal governance gaps.
For example, an organization may have strong controls around collecting and storing customer information but weaker oversight when that information is exported to analytics tools, shared with external providers, or retained after its original purpose has ended.
A lifecycle view prevents governance from focusing only on where data is stored.
Step 4: Assess the current state of data governance
Once the data environment is understood, the organization should assess its existing governance arrangements.
The purpose of this assessment is to establish a baseline.
Review how decisions involving data are currently made, which policies exist, whether accountability is clearly assigned, how risks are assessed, how data is classified, what controls operate, and how governance performance is reported to leadership.
The assessment should also consider whether existing processes are consistent across departments.
Large organizations often discover that individual business units have developed their own approaches to data governance. One department may have mature classification and ownership practices while another relies on informal knowledge and undocumented processes.
Identifying these differences helps leadership prioritize improvements based on risk rather than attempting to redesign everything simultaneously.
Step 5: Define the desired data governance outcomes
An ISO 38505 programme should have clear outcomes rather than becoming an open-ended documentation exercise.
The 2026 standard addresses good governance of data in relation to areas including effective performance, responsible stewardship, and ethical behaviour.
Organizations should translate these governance concepts into objectives relevant to their environment.
For example, desired outcomes may include improving accountability for critical datasets, reducing inappropriate access, increasing confidence in data used for strategic decisions, improving data quality, strengthening privacy governance, reducing unnecessary retention, or improving oversight of data used by AI systems.
Clear outcomes allow the organization to measure whether its governance programme is producing meaningful business value.
Step 6: Establish a data governance policy
The organization should develop a governance policy that translates leadership expectations into clear organizational direction.
The policy should define the purpose of data governance, governance roles, decision-making authority, accountability expectations, risk management requirements, classification principles, monitoring expectations, and escalation processes.
It should also establish relationships with supporting policies covering areas such as information security, privacy, retention, acceptable use, AI, third-party management, and records management.
The goal is not to create a large policy library simply to demonstrate that documentation exists. Policies should establish clear expectations that can be connected with owners, controls, risks, and monitoring activities.
Step 7: Establish data accountability across the lifecycle
Accountability is a central element of effective data governance.
Organizations should be able to identify who is accountable when data is collected, stored, reported, used for decisions, distributed, and disposed of.
This becomes particularly important in complex environments where multiple departments or third parties interact with the same information.
Consider customer information that enters through a digital application, moves into a CRM system, is copied into a cloud analytics platform, contributes to management reporting, and is later processed by an AI system.
Several teams may touch that data, but governance still needs clear accountability throughout the process.
Accountability structures should therefore define decision rights, operational responsibilities, approval requirements, escalation mechanisms, and oversight responsibilities.
Step 8: Develop a risk-based data classification model
Organizations should not apply identical controls to every piece of information.
A public press release and a database containing sensitive customer information have very different risk profiles.
A structured classification system helps determine how information should be protected and managed based on factors such as sensitivity, value, legal requirements, business criticality, and potential impact if compromised or misused.
The wider ISO 38505 series includes ISO/IEC TS 38505-3:2021, which specifically provides guidance on data classification in relation to data governance.
A classification model might distinguish between public, internal, confidential, and highly restricted information, although organizations should develop categories appropriate to their environment.
Classification should then influence decisions about access, encryption, sharing, storage, retention, monitoring, and disposal.
Step 9: Identify and assess data-related risks
Effective data governance requires a structured understanding of risk.
Organizations should identify scenarios that could affect the confidentiality, integrity, availability, quality, lawful use, ethical use, or business value of important data.
Relevant risks may include unauthorized access, accidental disclosure, poor data quality, excessive retention, inappropriate sharing, regulatory violations, third-party exposure, loss of critical information, unreliable analytics, and inappropriate use of data within AI systems.
Each significant risk should have an accountable owner and a defined treatment approach.
Connect data risk with enterprise risk
Data risks should not remain isolated within technical risk registers.
A failure involving important data can create financial loss, operational disruption, regulatory action, reputational damage, customer harm, or poor strategic decisions.
Data-related risks should therefore be connected with the wider enterprise risk management process where appropriate.
This allows leadership to evaluate data risk alongside other business risks and make better decisions about priorities and investment.
Step 10: Map legal, regulatory, contractual, and policy constraints
Data does not operate in a governance vacuum.
Organizations may be subject to privacy laws, cyber security regulations, sector-specific requirements, contractual commitments, intellectual property restrictions, data localization requirements, internal policies, and other constraints.
ISO 38505 implementation should therefore include a structured process for identifying requirements that affect how important data can be collected, processed, stored, transferred, retained, and disposed of.
The specific requirements will vary significantly between organizations and jurisdictions.
A multinational organization, for example, may need to manage different regulatory requirements across the European Union, United States, Middle East, Asia, and other regions while maintaining a consistent enterprise data governance model.
This is one reason data governance should be closely connected with GRC.
Step 11: Design and implement appropriate controls
Once risks and requirements have been identified, organizations need controls that translate governance direction into operational practice.
Controls can be administrative, technical, organizational, or physical.
Examples may include access reviews, approval workflows, encryption, retention controls, data loss prevention, classification requirements, logging, data quality checks, third-party assessments, backup processes, employee training, and secure disposal procedures.
The control environment should be proportionate to risk.
A mature implementation also establishes clear relationships between controls and the risks, policies, requirements, and datasets they support. This traceability makes it easier to understand why a control exists and what could happen if it fails.
Step 12: Apply the Evaluate, Direct and Monitor governance cycle
ISO 38505 builds on the governance model of ISO/IEC 38500 and uses an ongoing model in which governing bodies evaluate, direct, and monitor the organization’s use of data.
These activities should become part of the organization’s normal governance processes rather than being treated as a one-time implementation phase.
Evaluate
The governing body should evaluate the organization’s current and proposed use of data.
This involves considering business needs, opportunities, risks, stakeholder expectations, legal constraints, technology changes, and the potential consequences of important data-related decisions.
Evaluation should occur before major decisions and continue as conditions change.
Direct
Based on that evaluation, the governing body establishes direction.
Direction can take the form of strategies, policies, priorities, investment decisions, risk appetite, accountability structures, and expectations for management.
Management can then translate this direction into operational plans, processes, technologies, and controls.
Monitor
The governing body needs reliable information about whether its direction is being followed and whether expected outcomes are being achieved.
Monitoring can include risk indicators, control performance, policy exceptions, data incidents, audit findings, compliance status, remediation progress, data quality measures, and other governance metrics.
This closes the governance loop and provides information for future evaluation.
Step 13: Establish meaningful data governance metrics
Data governance needs measurable indicators if leadership is expected to monitor its effectiveness.
Metrics should provide insight into outcomes and risk rather than simply counting activities.
For example, organizations may monitor the percentage of critical datasets with assigned owners, overdue access reviews, unresolved high-risk findings, policy exceptions, data incidents, third-party data risks, retention violations, control effectiveness, or remediation completion.
Metrics should be tailored to the organization’s objectives and risk profile.
A board does not need hundreds of operational statistics. It needs reliable information that explains whether important data is being governed effectively and where intervention may be required.
Step 14: Integrate data governance with cyber security, privacy, AI, and GRC
Data governance should not become another organizational silo.
The same data may simultaneously be subject to cyber security controls, privacy obligations, regulatory requirements, enterprise risk considerations, contractual restrictions, and AI governance requirements.
Running each programme independently can create duplicated controls, conflicting policies, inconsistent ownership, and repeated evidence requests.
A more mature approach connects these disciplines.
For example, a control restricting privileged access to sensitive customer data may support information security requirements, privacy obligations, internal policy, regulatory expectations, and AI governance requirements at the same time.
Connecting these relationships creates a more efficient governance environment and provides leadership with a clearer view of organizational risk.
Step 15: Maintain evidence and governance records
Organizations should maintain sufficient records to demonstrate how governance decisions and controls operate.
Relevant evidence can include risk assessments, policies, approvals, meeting records, access reviews, control assessments, classification records, third-party reviews, monitoring results, incident records, remediation activities, and management reports.
Evidence should be connected with the relevant governance requirement or control whenever possible.
This is particularly valuable when the organization is also managing regulatory obligations or standards such as ISO 27001, GDPR, NIST, SOC 2, DORA, NIS2, or regional cyber security frameworks.
A connected evidence model reduces duplicated work and improves traceability.
Step 16: Monitor controls and identify governance gaps
Controls should not be assumed to remain effective simply because they were implemented correctly.
Technology changes, employees change roles, new suppliers are introduced, business processes evolve, regulations change, and AI systems create new uses for existing datasets.
Organizations therefore need ongoing monitoring.
Control failures, overdue activities, policy exceptions, new risks, and changing regulatory requirements should be identified early enough for management to respond.
This shifts data governance away from periodic review toward continuous oversight.
Step 17: Review and continually improve your ISO 38505 implementation
Data governance is an ongoing practice.
The ISO 38505 approach recognizes that governance needs to adapt as the data landscape changes. Organizations should therefore periodically review governance arrangements, risks, policies, responsibilities, controls, stakeholder expectations, and monitoring mechanisms.
Reviews should also take place when significant changes occur.
Examples include acquisitions, entry into new markets, adoption of major cloud platforms, new regulatory requirements, significant security incidents, deployment of AI systems, or major changes to how customer information is processed.
The objective is to ensure that governance continues to reflect the organization’s actual data environment rather than the environment that existed when the programme was first designed.
Common mistakes when implementing ISO 38505
Organizations can weaken implementation by treating ISO 38505 as a documentation exercise.
One common mistake is assigning the entire programme to IT. Data governance requires technical expertise, but many important decisions involve business strategy, risk, legal obligations, ethics, privacy, and stakeholder expectations.
Another mistake is focusing heavily on policies while giving limited attention to accountability and monitoring. A well-written data governance policy provides little assurance if no one owns the relevant risks and controls.
Organizations can also create unnecessary complexity by establishing separate governance structures for every standard or regulation. Where requirements overlap, controls and evidence should be reused appropriately.
Finally, organizations should avoid assuming that implementation ends once the initial governance model is established. Data environments change too quickly for static governance to remain effective.
How long does it take to implement ISO 38505?
There is no universal ISO 38505 implementation timeline.
The time required depends on the organization’s size, existing governance maturity, complexity of its data environment, number of jurisdictions, regulatory exposure, existing policies and controls, and availability of accountable stakeholders.
An organization with mature information security, privacy, enterprise risk, and data management programmes may already have many necessary components in place.
A large multinational organization with fragmented data ownership, multiple cloud environments, extensive third-party processing, and several regulatory regimes may require a longer implementation programme.
The more useful objective is therefore not to target an arbitrary implementation date, but to establish priorities based on risk and progressively mature the governance environment.
Is ISO 38505 certification required?
Organizations should not approach ISO 38505 as though it were equivalent to a conventional management-system certification standard such as ISO/IEC 27001.
ISO/IEC 38505-1:2026 provides principles for governing bodies concerning the governance and use of data. Its purpose is to guide effective, efficient, and acceptable data governance.
Organizations should therefore focus on applying its principles effectively and demonstrating strong governance outcomes rather than building the programme solely around obtaining a certificate.
ISO 38505 implementation checklist
A practical implementation should leave the organization able to demonstrate that data governance has been integrated into organizational governance.
Before considering the initial implementation mature, confirm that the organization has established executive sponsorship, identified stakeholders, understood important data and its lifecycle, assigned accountability, established governance policies, classified important data, assessed data-related risks, identified applicable constraints, implemented controls, and created meaningful monitoring and reporting.
The organization should also be able to show that governance follows an ongoing evaluate, direct, and monitor cycle and that data governance is connected with cyber security, privacy, compliance, enterprise risk, and AI governance where relevant.
The checklist should be used as a management aid rather than as a substitute for the standard itself.
Conclusion: Implement ISO 38505 with a connected GRC approach
Organizations looking to implement ISO 38505 need to build a governance model that works beyond the initial implementation project.
Data ownership needs to remain visible. Risks need to be reassessed. Policies need owners and review cycles. Controls need monitoring. Evidence needs to remain current. Governance issues need clear remediation paths, while leadership needs meaningful information to evaluate whether data continues to be used effectively, responsibly, and in line with organizational objectives.
Managing these relationships through separate spreadsheets, emails, policy folders, risk registers, and compliance tools makes governance increasingly difficult as the organization grows.
At CyberArrow, we help organizations bring these activities together through CyberArrow GRC.
Our platform connects governance, enterprise risk management, compliance, internal controls, policies, evidence, audit readiness, and reporting within a centralized GRC environment. CyberArrow can automate risk assessments, compliance workflows, and evidence collection while providing continuous internal control monitoring and real-time visibility into control performance. Our platform also supports 80+ integrations, helping organizations connect GRC activities with the technologies already operating across their environment.
For an ISO 38505 programme, this can help teams establish clearer relationships between data-related risks, responsible owners, governance policies, internal controls, evidence, findings, and remediation. Instead of rebuilding governance records before each review, organizations can maintain a more continuous view of whether controls and governance activities are operating as expected.
CyberArrow GRC can also help organizations manage multiple standards and regulatory requirements within the same environment. This becomes particularly useful when data governance overlaps with ISO 27001, NIST, GDPR, NIS2, DORA, SOC 2, regional cybersecurity frameworks, and emerging AI governance requirements.
We are trusted by the world’s biggest brands across the US, Europe, Africa, Asia, and the Middle East, with organizations including IKEA, Emirates, American Express, Vodafone, and Revolut featured among the brands using CyberArrow.
ISO 38505 provides the governance principles. The next challenge is turning those principles into accountable processes that continue to operate as data, technology, regulation, and business priorities change.
At CyberArrow, that is where we help.
Want to strengthen data governance while reducing manual GRC work? Book a free CyberArrow GRC demo and see how we can help you connect risks, controls, policies, evidence, and governance monitoring in one platform.
Frequently asked questions about implementing ISO 38505
How do you implement ISO 38505?
To implement ISO 38505, organizations should establish executive accountability for data governance, understand their data environment, identify stakeholders, define governance outcomes, assign data ownership, assess risks, establish classification and policies, implement controls, and create ongoing monitoring. The governance process should support continuous evaluation, direction, and monitoring rather than operate as a one-time compliance project.
What is the first step in ISO 38505 implementation?
The first practical step is establishing governance sponsorship and accountability. ISO/IEC 38505-1 is directed primarily at governing bodies, so implementation should have appropriate executive involvement rather than being treated solely as an IT or cyber security project.
What version of ISO 38505 should organizations implement in 2026?
Organizations should use ISO/IEC 38505-1:2026, the second edition published in August 2026. It replaced ISO/IEC 38505-1:2017, which has been withdrawn.
Does ISO 38505 only apply to large enterprises?
No. ISO states that ISO/IEC 38505-1:2026 applies to organizations of all sizes and includes private and public companies, government entities, and not-for-profit organizations regardless of the extent to which they depend on data.
How does GRC software help implement ISO 38505?
GRC software can support implementation by centralizing risks, controls, policies, responsibilities, evidence, assessments, remediation activities, and reporting. It can also help organizations maintain traceability between governance requirements and operational controls and provide ongoing visibility into control effectiveness and risk.